صرف دکھائی دے رہا ہے
0:08
S… Speaker 1 (2026-04-13 08-52-50)
In this video,
0:08
S… Speaker 2 (2026-04-13 08-52-50)
we're going to go over what Splunk is and
0:13
S… Speaker 2 (2026-04-13 08-52-50)
how it can be used in threat hunting.
0:16
S… Speaker 1 (2026-04-13 08-52-50)
So to start off with,
0:18
S… Speaker 2 (2026-04-13 08-52-50)
what is Splunk?
0:19
S… Speaker 2 (2026-04-13 08-52-50)
If you are not familiar with Splunk,
0:21
S… Speaker 2 (2026-04-13 08-52-50)
it is a security information and event management system,
0:25
S… Speaker 2 (2026-04-13 08-52-50)
or a SIEM or SIEM,
0:27
S… Speaker 2 (2026-04-13 08-52-50)
depending on how you want to pronounce it.
0:29
S… Speaker 2 (2026-04-13 08-52-50)
It's used for a lot more than just security.
0:33
S… Speaker 2 (2026-04-13 08-52-50)
A lot of organizations use it for things like system monitoring,
0:37
S… Speaker 2 (2026-04-13 08-52-50)
performance information,
0:39
S… Speaker 2 (2026-04-13 08-52-50)
error correlation,
0:40
S… Speaker 2 (2026-04-13 08-52-50)
things like that.
0:41
S… Speaker 2 (2026-04-13 08-52-50)
For our purposes,
0:42
S… Speaker 2 (2026-04-13 08-52-50)
we're going to be looking at it from a threat hunting perspective.
0:46
S… Speaker 2 (2026-04-13 08-52-50)
It's capable of performing analysis on logs
0:50
S… Speaker 2 (2026-04-13 08-52-50)
and other data that is fed into the system,
0:54
S… Speaker 2 (2026-04-13 08-52-50)
and it can collect logs from multiple different sources,
0:59
S… Speaker 2 (2026-04-13 08-52-50)
performing both aggregation and correlation activities,
1:04
S… Speaker 2 (2026-04-13 08-52-50)
basically tying logs together from multiple different systems to
1:08
S… Speaker 2 (2026-04-13 08-52-50)
kind of build the story about what's been happening on those systems
1:13
S… Speaker 2 (2026-04-13 08-52-50)
and on the network in general.
1:15
S… Speaker 2 (2026-04-13 08-52-50)
It does have capabilities for real -time analysis.
1:18
S… Speaker 2 (2026-04-13 08-52-50)
There are a lot of alerting capabilities included in
1:23
S… Speaker 2 (2026-04-13 08-52-50)
Splunk, and a lot of organizations will use Splunk as part of their security
1:27
S… Speaker 2 (2026-04-13 08-52-50)
operations center as well.
1:29
S… Speaker 2 (2026-04-13 08-52-50)
for the alerting and also for the dashboards
1:34
S… Speaker 2 (2026-04-13 08-52-50)
and visualizations capabilities that Splunk has inside.
1:38
S… Speaker 1 (2026-04-13 08-52-50)
Now,
1:39
S… Speaker 2 (2026-04-13 08-52-50)
for the most part in threat hunting,
1:41
S… Speaker 2 (2026-04-13 08-52-50)
we're not really going to be taking a look at the dashboards because those are going to be more
1:45
S… Speaker 2 (2026-04-13 08-52-50)
of reactive measures waiting for Splunk to
1:49
S… Speaker 2 (2026-04-13 08-52-50)
analyze data and show information on those dashboards where
1:54
S… Speaker 2 (2026-04-13 08-52-50)
threat hunting is more of a proactive activity.
1:58
S… Speaker 2 (2026-04-13 08-52-50)
Visualizations can sometimes be used in threat hunting just basically
2:02
S… Speaker 2 (2026-04-13 08-52-50)
as a way to show the data a bit more cleaner,
2:06
S… Speaker 2 (2026-04-13 08-52-50)
and we'll take a look at some forms of visualizations like
2:10
S… Speaker 2 (2026-04-13 08-52-50)
tables and things like that as we go through this course and start working
2:15
S… Speaker 2 (2026-04-13 08-52-50)
with Splunk a bit more.
2:17
S… Speaker 2 (2026-04-13 08-52-50)
One thing that is very common to use in threat hunting
2:21
S… Speaker 2 (2026-04-13 08-52-50)
with Splunk is raw searches of the logs.
2:24
S… Speaker 1 (2026-04-13 08-52-50)
And this is done in Splunk,
2:27
S… Speaker 2 (2026-04-13 08-52-50)
specifically using what's known as SPL,
2:29
S… Speaker 2 (2026-04-13 08-52-50)
the Splunk Processing Language.
2:32
S… Speaker 2 (2026-04-13 08-52-50)
That is the language that's used to craft the queries
2:36
S… Speaker 2 (2026-04-13 08-52-50)
that are used to search through logs in Splunk.
2:39
S… Speaker 2 (2026-04-13 08-52-50)
We'll take a look at SPL in more detail in a later video
2:43
S… Speaker 2 (2026-04-13 08-52-50)
in this course,
2:44
S… Speaker 1 (2026-04-13 08-52-50)
though.
2:45
S… Speaker 2 (2026-04-13 08-52-50)
It also has a lot of options for add
2:49
S… Speaker 2 (2026-04-13 08-52-50)
-on applications from various different vendors and security
2:53
S… Speaker 2 (2026-04-13 08-52-50)
providers to kind of expand upon the functionality that's
2:58
S… Speaker 2 (2026-04-13 08-52-50)
included in Splunk by default.
3:00
S… Speaker 2 (2026-04-13 08-52-50)
For the purposes of threat hunting,
3:02
S… Speaker 2 (2026-04-13 08-52-50)
though, we're not going to be looking at any of that.
3:04
S… Speaker 2 (2026-04-13 08-52-50)
The most important thing we're going to be looking at is the raw searches.
3:08
S… Speaker 1 (2026-04-13 08-52-50)
Again,
3:09
S… Speaker 2 (2026-04-13 08-52-50)
with a little bit of visualization kind of sprinkled in there,
3:12
S… Speaker 1 (2026-04-13 08-52-50)
if you will.
3:13
S… Speaker 2 (2026-04-13 08-52-50)
So Splunk has a very specific architecture that
3:18
S… Speaker 2 (2026-04-13 08-52-50)
you should be aware of.
3:19
S… Speaker 2 (2026-04-13 08-52-50)
The key component of Splunk is the indexer.
3:24
S… Speaker 2 (2026-04-13 08-52-50)
It is in charge of storing and organizing all
3:28
S… Speaker 2 (2026-04-13 08-52-50)
of the log information that is fed into it through a number
3:32
S… Speaker 2 (2026-04-13 08-52-50)
of forwarders.
3:33
S… Speaker 2 (2026-04-13 08-52-50)
The forwarder's jobs are to collect and send data
3:37
S… Speaker 2 (2026-04-13 08-52-50)
to the indexer.
3:39
S… Speaker 1 (2026-04-13 08-52-50)
Now, in this case,
3:40
S… Speaker 2 (2026-04-13 08-52-50)
we're talking about forwarders in this kind of instance as kind of a generic term
3:44
S… Speaker 2 (2026-04-13 08-52-50)
for anything that sends log data to the
3:49
S… Speaker 2 (2026-04-13 08-52-50)
indexer.
3:50
S… Speaker 2 (2026-04-13 08-52-50)
There is an actual Splunk forwarder kind of application
3:54
S… Speaker 2 (2026-04-13 08-52-50)
that can be installed on systems to help with that.
3:57
S… Speaker 1 (2026-04-13 08-52-50)
But in this instance,
3:59
S… Speaker 2 (2026-04-13 08-52-50)
we're using forwarder in more of the generic term,
4:02
S… Speaker 1 (2026-04-13 08-52-50)
if you will.
4:03
S… Speaker 1 (2026-04-13 08-52-50)
Now,
4:03
S… Speaker 2 (2026-04-13 08-52-50)
coupled with the indexer,
4:05
S… Speaker 2 (2026-04-13 08-52-50)
you also have what's known as the search head.
4:08
S… Speaker 2 (2026-04-13 08-52-50)
This is kind of what provides the interface for
4:12
S… Speaker 2 (2026-04-13 08-52-50)
running searches,
4:13
S… Speaker 2 (2026-04-13 08-52-50)
showing dashboards,
4:15
S… Speaker 2 (2026-04-13 08-52-50)
that kind of thing.
4:16
S… Speaker 2 (2026-04-13 08-52-50)
and the data from the indexer is what's included in those searches.
4:20
S… Speaker 2 (2026-04-13 08-52-50)
Now, the indexer and the search head can be on one system,
4:24
S… Speaker 2 (2026-04-13 08-52-50)
or it can be spread across multiple indexers,
4:28
S… Speaker 2 (2026-04-13 08-52-50)
multiple search heads.
4:29
S… Speaker 2 (2026-04-13 08-52-50)
That's going to really depend on the amount of data being ingested
4:34
S… Speaker 1 (2026-04-13 08-52-50)
into Splunk,
4:35
S… Speaker 2 (2026-04-13 08-52-50)
the requirements the organization has,
4:38
S… Speaker 2 (2026-04-13 08-52-50)
the deployment model that's being used.
4:41
S… Speaker 2 (2026-04-13 08-52-50)
For the sake of what we're looking at in our labs
4:45
S… Speaker 2 (2026-04-13 08-52-50)
and in everything,
4:46
S… Speaker 2 (2026-04-13 08-52-50)
this is all kind of an all -in -one system.
4:49
S… Speaker 2 (2026-04-13 08-52-50)
So you can have just one server running both the
4:53
S… Speaker 2 (2026-04-13 08-52-50)
indexer and search head,
4:55
S… Speaker 2 (2026-04-13 08-52-50)
or you can have multiple indexers and multiple search heads.
4:58
S… Speaker 1 (2026-04-13 08-52-50)
But now let's...
5:00
S… Speaker 1 (2026-04-13 08-52-50)
take a break from the slides and move over into our lab environment
5:04
S… Speaker 1 (2026-04-13 08-52-50)
and take a look at Splunk really quick just so you're familiar with the interface
5:08
S… Speaker 1 (2026-04-13 08-52-50)
before we jump in and start working on writing queries.
5:12
S… Speaker 1 (2026-04-13 08-52-50)
So when you first log into Splunk this is
5:16
S… Speaker 1 (2026-04-13 08-52-50)
kind of the interface you'll be looking at.
5:19
S… Speaker 1 (2026-04-13 08-52-50)
This is where you can have different applications loaded into Splunk,
5:23
S… Speaker 1 (2026-04-13 08-52-50)
but the main component we're going to be concerned about when it comes to threat hunting
5:27
S… Speaker 1 (2026-04-13 08-52-50)
is the search and reporting section here on the
5:31
S… Speaker 1 (2026-04-13 08-52-50)
far left.
5:34
S… Speaker 1 (2026-04-13 08-52-50)
So we go into the search and reporting section,
5:36
S… Speaker 1 (2026-04-13 08-52-50)
and to start off with,
5:37
S… Speaker 1 (2026-04-13 08-52-50)
it's very simple.
5:38
S… Speaker 1 (2026-04-13 08-52-50)
We have our search box.
5:39
S… Speaker 1 (2026-04-13 08-52-50)
We have some search history and some information here.
5:42
S… Speaker 1 (2026-04-13 08-52-50)
One thing you can look at to see what kind of data
5:46
S… Speaker 1 (2026-04-13 08-52-50)
you have in Splunk is the data summary.
5:49
S… Speaker 1 (2026-04-13 08-52-50)
So if you click on the data summary,
5:51
S… Speaker 1 (2026-04-13 08-52-50)
you can see exactly what kind of information you have in this
5:55
S… Speaker 1 (2026-04-13 08-52-50)
system.
5:55
S… Speaker 1 (2026-04-13 08-52-50)
So we have logs from three different sources here,
5:59
S… Speaker 1 (2026-04-13 08-52-50)
three different hosts.
6:01
S… Speaker 1 (2026-04-13 08-52-50)
We have different types,
6:03
S… Speaker 1 (2026-04-13 08-52-50)
basically sources.
6:04
S… Speaker 1 (2026-04-13 08-52-50)
So we have a lot of information from our Windows event logs,
6:07
S… Speaker 1 (2026-04-13 08-52-50)
including things like PowerShell and Sysmon,
6:11
S… Speaker 1 (2026-04-13 08-52-50)
as you can see right here.
6:12
S… Speaker 1 (2026-04-13 08-52-50)
And then we have a source types as well.
6:16
S… Speaker 1 (2026-04-13 08-52-50)
It's a different way of organizing the data.
6:19
S… Speaker 1 (2026-04-13 08-52-50)
Now, when you are looking at Splunk and
6:23
S… Speaker 1 (2026-04-13 08-52-50)
doing searches in Splunk,
6:24
S… Speaker 1 (2026-04-13 08-52-50)
one of the key things you need to keep in mind is over
6:29
S… Speaker 1 (2026-04-13 08-52-50)
here on the right -hand side,
6:30
S… Speaker 1 (2026-04-13 08-52-50)
and I'll make that a little easier to see,
6:34
S… Speaker 1 (2026-04-13 08-52-50)
the right -hand side right there where it says last 24 hours.
6:39
S… Speaker 1 (2026-04-13 08-52-50)
The key you need to keep in mind there is to make sure whatever the
6:43
S… Speaker 1 (2026-04-13 08-52-50)
time frame for the threat hunt you're performing,
6:46
S… Speaker 1 (2026-04-13 08-52-50)
you have selected properly in here.
6:50
S… Speaker 1 (2026-04-13 08-52-50)
There's a lot of presets you can use,
6:52
S… Speaker 1 (2026-04-13 08-52-50)
including relative time information,
6:54
S… Speaker 1 (2026-04-13 08-52-50)
and also one that just covers logs,
6:56
S… Speaker 1 (2026-04-13 08-52-50)
all of the logs that are included in Splunk.
7:00
S… Speaker 1 (2026-04-13 08-52-50)
You have real -time options for,
7:03
S… Speaker 1 (2026-04-13 08-52-50)
you know, 24 hours ago.
7:04
S… Speaker 1 (2026-04-13 08-52-50)
You can specify date ranges,
7:07
S… Speaker 1 (2026-04-13 08-52-50)
date and time ranges,
7:08
S… Speaker 1 (2026-04-13 08-52-50)
all kinds of things.
7:09
S… Speaker 1 (2026-04-13 08-52-50)
So for the purposes of just kind of what we're looking at here,
7:13
S… Speaker 1 (2026-04-13 08-52-50)
we're going to be looking at...
7:16
S… Speaker 1 (2026-04-13 08-52-50)
all time just to make it simple to make sure we're including all
7:20
S… Speaker 1 (2026-04-13 08-52-50)
of our logs here.
7:23
S… Speaker 1 (2026-04-13 08-52-50)
I also mentioned earlier that Splunk is capable of doing things like
7:27
S… Speaker 1 (2026-04-13 08-52-50)
real -time alerting,
7:28
S… Speaker 1 (2026-04-13 08-52-50)
and that's where alerts would show up here in this alerts section.
7:31
S… Speaker 2 (2026-04-13 08-52-50)
Of course,
7:32
S… Speaker 1 (2026-04-13 08-52-50)
with the free version of Splunk,
7:34
S… Speaker 1 (2026-04-13 08-52-50)
alerting is not included.
7:35
S… Speaker 1 (2026-04-13 08-52-50)
You also have dashboards that can be configured in here,
7:38
S… Speaker 1 (2026-04-13 08-52-50)
and there are some default dashboards that are included.
7:41
S… Speaker 2 (2026-04-13 08-52-50)
But again,
7:42
S… Speaker 1 (2026-04-13 08-52-50)
for the purposes of threat hunting,
7:45
S… Speaker 1 (2026-04-13 08-52-50)
we're going to be looking primarily at just the searching.
7:49
S… Speaker 1 (2026-04-13 08-52-50)
Now, we'll get into this when we start talking about SPL and how to construct
7:53
S… Speaker 1 (2026-04-13 08-52-50)
different queries in Splunk.
7:55
S… Speaker 1 (2026-04-13 08-52-50)
But one of the main things you have to keep in mind when you're making these searches,
7:59
S… Speaker 1 (2026-04-13 08-52-50)
besides the time frame,
8:01
S… Speaker 1 (2026-04-13 08-52-50)
which you can see as we switch screens at reset,
8:03
S… Speaker 1 (2026-04-13 08-52-50)
we'll set it back to all time here,
8:05
S… Speaker 1 (2026-04-13 08-52-50)
is that all data in Splunk is stored in an
8:09
S… Speaker 1 (2026-04-13 08-52-50)
index.
8:09
S… Speaker 1 (2026-04-13 08-52-50)
There are or can be multiple different indexes
8:14
S… Speaker 1 (2026-04-13 08-52-50)
in any given Splunk installation.
8:17
S… Speaker 1 (2026-04-13 08-52-50)
And that just depends on,
8:19
S… Speaker 1 (2026-04-13 08-52-50)
you know, what the organization needs,
8:21
S… Speaker 1 (2026-04-13 08-52-50)
how the organization wants to organize the logging information,
8:24
S… Speaker 1 (2026-04-13 08-52-50)
things like that.
8:25
S… Speaker 1 (2026-04-13 08-52-50)
There is a default index included in
8:30
S… Speaker 1 (2026-04-13 08-52-50)
Splunk that's called main.
8:32
S… Speaker 2 (2026-04-13 08-52-50)
Typically,
8:33
S… Speaker 1 (2026-04-13 08-52-50)
best practices say to not put production data in
8:37
S… Speaker 1 (2026-04-13 08-52-50)
that index and to use a custom index.
8:41
S… Speaker 1 (2026-04-13 08-52-50)
For the purposes of this course and our labs,
8:44
S… Speaker 1 (2026-04-13 08-52-50)
we will have an index called E -C -T -H -P.
8:48
S… Speaker 1 (2026-04-13 08-52-50)
And that is how we're going to be starting all of
8:52
S… Speaker 1 (2026-04-13 08-52-50)
our searches throughout this course when we're talking about Splunk.
8:56
S… Speaker 1 (2026-04-13 08-52-50)
They will start with index equals E -C -T -H -P.
9:00
S… Speaker 2 (2026-04-13 08-52-50)
We hit enter there,
9:01
S… Speaker 1 (2026-04-13 08-52-50)
and we should get basically all the logs included in this
9:05
S… Speaker 1 (2026-04-13 08-52-50)
lab.
9:06
S… Speaker 1 (2026-04-13 08-52-50)
So we see here we have 4 ,156
9:11
S… Speaker 1 (2026-04-13 08-52-50)
events recorded from that return,
9:16
S… Speaker 1 (2026-04-13 08-52-50)
excuse me,
9:17
S… Speaker 1 (2026-04-13 08-52-50)
from the search we just did.
9:20
S… Speaker 1 (2026-04-13 08-52-50)
And again, we just did a search for index equals ecthp.
9:24
S… Speaker 1 (2026-04-13 08-52-50)
which returns all of the data that is in
9:29
S… Speaker 1 (2026-04-13 08-52-50)
that index because there's no other qualifiers,
9:31
S… Speaker 1 (2026-04-13 08-52-50)
there's no other filters,
9:32
S… Speaker 1 (2026-04-13 08-52-50)
there's nothing else that we specified in this search.
9:36
S… Speaker 1 (2026-04-13 08-52-50)
So just a really quick introduction to Splunk,
9:41
S… Speaker 1 (2026-04-13 08-52-50)
how Splunk is architected,
9:43
S… Speaker 1 (2026-04-13 08-52-50)
and an introduction to what the interface looks like and
9:47
S… Speaker 1 (2026-04-13 08-52-50)
how we're going to be starting off with searches.
9:49
S… Speaker 1 (2026-04-13 08-52-50)
Again, as we progress through this course,
9:52
S… Speaker 1 (2026-04-13 08-52-50)
We'll be diving into a lot more detail on how to create queries
9:57
S… Speaker 1 (2026-04-13 08-52-50)
using SPL,
9:58
S… Speaker 1 (2026-04-13 08-52-50)
the Splunk processing language,
10:00
S… Speaker 1 (2026-04-13 08-52-50)
and more details of what we can look for,
10:04
S… Speaker 1 (2026-04-13 08-52-50)
how we can adjust the results to kind of pivot throughout the threat
10:08
S… Speaker 1 (2026-04-13 08-52-50)
hunt.
10:08
S… Speaker 1 (2026-04-13 08-52-50)
But we'll be getting into more details as we go through this course in separate
10:13
S… Speaker 1 (2026-04-13 08-52-50)
videos.

یہ نقل AI (خودکار بولنے کی پہچان) سے بنائی گئی تھی. غلطیاں ہو سکتے ہیں - اہم استعمال کے لیے اصل آڈیو کے مقابلے میں جانچیں. AI پالیسي

❤️ STT.ai سے محبت؟ اپنے دوستوں کو بتاؤ۔
خلاصہ
اس نقل کا AI خلاصہ پیدا کرنے کے لئے خلاصہ کرو کلک کریں.
خلاصہ...
اس نقل کے بارے ميں AI سے پوچھو
اس نقل کے بارے میں کچھ پوچھو - AI متعلقہ حصوں کو تلاش کرے گا اور جواب دے گا۔